Pith. sign in

Paper Citation Record · LEDGER

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming

As of 23 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 0 inbound Pith citation observations for arXiv:2608.05108.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.05108 v1

Coverage vector

measured 55 of 55 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T05:11:49.315668Z

measured 55 of 55 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

55 of 55 outbound references displayed

  • verified exact0
  • verified fuzzy26
  • unresolved28
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation ce8157a8-3198-4805-9f11-09358257bf05 · outbound

This paper cites Ignore previous prompt: Attack techniques for language models,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Ignore previous prompt: Attack techniques for language models,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.154237Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.154237Z digest=sha256:3e243b239271f62306df5635adac4df7e350d484c674fec1aba96dd38e2645f8

Observation f2f22714-4efa-45ed-94b5-9bd9f4957670 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.781256Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:45.267686Z digest=sha256:6e478a90eeba11889f25ccd0822d2bcf5ba4eb73f7aea6cf9aa98652426560d2

Observation bd61774f-d9cd-4278-95d3-dcd980725294 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Formalizing and benchmarking prompt injection attacks and defenses,

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.674740Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:45.327186Z digest=sha256:4486dd59ee3d7b423afaaf1380ff7965f734d9edb00769a7768b0618a1b5942f

Observation 76d5a701-c412-4fe4-a7c4-3195dff7f224 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool- integrated large language model agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Injecagent: Benchmarking indirect prompt injections in tool- integrated large language model agents,

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.473490Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:45.414814Z digest=sha256:368faaefca3ceb3449c0d4080eef0c972146eadd4741a6bef8841454c886ec6c

Observation bde26fa6-ac1b-4460-aa32-edc540ebccec · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.289540Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:45.463507Z digest=sha256:5ddb6891ab67f175f6cb1836f97a68726007de5a825665d2ad5b88ad8f502bff

Observation 14016feb-d5b0-4dd6-b8ab-4c41d96bc745 · outbound

This paper cites The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.495675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.495675Z digest=sha256:91c248c84bd8db805f46f31e8eb297b4d55be6b700c2930b3de263496e6c3b02

Observation 7c719ede-b99a-4713-8f57-90f3d7c72b39 · outbound

This paper cites Muse spark safety & preparedness report,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Muse spark safety & preparedness report,

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.149686Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:45.604178Z digest=sha256:fb0e4fcef6b09f733c8919777b6b3d14c84f879040bf5be423fe4bcc7785e13f

Observation 16083f83-3eea-4cce-ac70-1f620f990eab · outbound

This paper cites Claude opus 4.7 system card,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude opus 4.7 system card,

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.015812Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:45.676598Z digest=sha256:34e338b0c95d163800279f9a46fd43029c3a52aa27fb750b5402b070e1c997de

Observation 23e69e23-13f4-44f8-a68b-54603f45fa10 · outbound

This paper cites Datasentinel: A game-theoretic detection of prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Datasentinel: A game-theoretic detection of prompt injection attacks,

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.853663Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:45.725244Z digest=sha256:e72aa3983ab1ed2e5c17b85dc259164401f1eb98b15129f8b36e31fba941136a

Observation a610dc2b-5572-47b4-ba4c-9b8222a28ea6 · outbound

This paper cites PromptGuard Prompt Injection Guardrail,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PromptGuard Prompt Injection Guardrail,

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.674204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:45.794378Z digest=sha256:cda48b6c533d2c7fb3b4d7930f67a9e20f35b2e222feb4d86a357514c339404a

Observation f1bf1c37-421f-42e8-a85b-5263240f4e08 · outbound

This paper cites AgentWatcher: A Rule-based Prompt Injection Monitor.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming AgentWatcher: A Rule-based Prompt Injection Monitor

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.854500Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.854500Z digest=sha256:cd0ede29522ebd01282c3d0568f79a92f252d375cf34890d346c363b5339b463

Observation cb5317d7-a23e-4772-8e0c-cd71d6462d0b · outbound

This paper cites Meta secalign: A secure foundation llm against prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Meta secalign: A secure foundation llm against prompt injection attacks,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.943166Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.943166Z digest=sha256:0fea37bf78072a7241a8ad74822566b474a148bb074c26b918edb5d9f1a2043f

Observation fccb7cd8-214d-4419-9e71-61df4f9a1633 · outbound

This paper cites Purple-teaming LLMs with Adversarial Defender Training.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Purple-teaming LLMs with Adversarial Defender Training

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.995659Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.995659Z digest=sha256:7ad43c9dc0685052bb81daa12bba8b2a7ffa4e265de9f12da75851e78ba4ac2b

Observation 128eff0f-a175-4f43-85ee-a0e8d2807bf2 · outbound

This paper cites Black-box red-teaming of multi-agent systems via reinforcement learning,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Black-box red-teaming of multi-agent systems via reinforcement learning,

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.546133Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:46.063263Z digest=sha256:e06e82361b58c939b5ac4be865e7758abfe217fa0a3b522dd7fbf98ced909502

Observation 1506dadd-4cfc-4288-87d3-46cd75cdeb52 · outbound

This paper cites Learning to Inject: Automated Prompt Injection via Reinforcement Learning.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Learning to Inject: Automated Prompt Injection via Reinforcement Learning

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.111393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.111393Z digest=sha256:cd3cb16de3da36e9b563f22f431a3d981551e29efe31824ee3205c081c1b7eb7

Observation 6058760e-f676-4eeb-be9d-2d872b0e74d7 · outbound

This paper cites Rl is a hammer and llms are nails: A simple reinforcement learning recipe for strong prompt injection,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Rl is a hammer and llms are nails: A simple reinforcement learning recipe for strong prompt injection,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.203274Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.203274Z digest=sha256:19a591da067bfe0b91d186dc575c909c6a59aa63ca85433124a54b543643e92f

Observation f8e5973a-ec6c-48b5-8515-b3a7e9413797 · outbound

This paper cites PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.310041Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.310041Z digest=sha256:363c251a7c7dfaf47dab76e8f97df0f418b47918bad8a76ccea538c0043e1d51

Observation 40477b0a-9b12-4a28-bfe1-36da9440ec23 · outbound

This paper cites Tree of attacks: Jailbreaking black-box llms automatically,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Tree of attacks: Jailbreaking black-box llms automatically,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.382227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.382227Z digest=sha256:0a765ad6cf52da88949301e6d7e71304cb617e4f61f90d640a966c8b6e1cf7e7

Observation 7986393b-053b-411a-9513-0af5e38c9095 · outbound

This paper cites Jailbreaking black box large language models in twenty queries,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Jailbreaking black box large language models in twenty queries,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.449184Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.449184Z digest=sha256:66a0c8dd737a8194373cef9dc032ad2cc249dec06dd411b2d85c55078e74a27b

Observation 8b07b5e7-5bfc-4f94-a98d-05a9ccd7b76a · outbound

This paper cites Agentvigil: Automatic black-box red-teaming for indirect prompt injection against llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Agentvigil: Automatic black-box red-teaming for indirect prompt injection against llm agents,

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.370992Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:46.532386Z digest=sha256:7f2fe95abe06cdd38d8b68e165d0b9861d4b238df7c50d581dfb67463f385f99

Observation 975147fa-4954-4812-8b14-8f12eb3df08d · outbound

This paper cites Piarena: A platform for prompt injection evaluation,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Piarena: A platform for prompt injection evaluation,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.198269Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:46.588128Z digest=sha256:702d710be3eab47e294f87ab11e6270c56edae06a6e21712be29dc93de70e937

Observation d4dae2ee-2ff0-427c-83aa-68f923b3ab64 · outbound

This paper cites Gpt-red: Automated red teaming via self-play at scale.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Gpt-red: Automated red teaming via self-play at scale

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.032827Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:46.654896Z digest=sha256:ca365cf1463d8270339d88844bff3067a43007dd71de4cd8bd83554fc6f7a144

Observation 6b1bbc84-dceb-4cd5-8669-4c88c9828352 · outbound

This paper cites How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.711658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.711658Z digest=sha256:52640db50a0f7f2c26a3242c1ee8be960ccac2a5aa087ca77ceab322a4e8f850

Observation f286f7ff-181a-40e7-8e00-de6f0b86b501 · outbound

This paper cites Muzzle: Adaptive agentic red-teaming of web agents against indirect prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Muzzle: Adaptive agentic red-teaming of web agents against indirect prompt injection attacks,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.767256Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.767256Z digest=sha256:95bad41c4e8cc02b448cd92f84ff6a2f029f8f8c6dfa28a3cd0dd8104f6dbbb4

Observation 66b2b30e-52df-4521-8173-9b09574fa6b6 · outbound

This paper cites Autodan- turbo: A lifelong agent for strategy self-exploration to jailbreak llms,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Autodan- turbo: A lifelong agent for strategy self-exploration to jailbreak llms,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.785109Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:46.906206Z digest=sha256:9572abab4b71e6ba843ac926c87796f4401305d1673c33ba49c95a4443f9baf1

Observation 773492fa-d159-4a91-b778-4d6aac32070e · outbound

This paper cites DecodingTrust-Agent Platform (DTap): A Controllable and Interactive Red-Teaming Platform for AI Agents.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming DecodingTrust-Agent Platform (DTap): A Controllable and Interactive Red-Teaming Platform for AI Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.996106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.996106Z digest=sha256:40c223c1818342458a0a6ab75d3e449e83140307ab7d51baf809a3011f5f5830

Observation ef34a227-74f2-469e-9719-296058853a8b · outbound

This paper cites ReAct: Synergizing Reasoning and Acting in Language Models.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ReAct: Synergizing Reasoning and Acting in Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.055268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.055268Z digest=sha256:797c329fc6efacfb4c33b66a0b1a87575e15f3cf561df3e2725a3de2911940f9

Observation 83da0063-c6d1-44d6-ad44-f293bc8c0929 · outbound

This paper cites Toolllm: Facilitating large language models to master 16000+ real-world apis,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Toolllm: Facilitating large language models to master 16000+ real-world apis,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.496789Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.096713Z digest=sha256:d4dc793dc18ba6359ea6e9db0d2178a7fb4f4337acd05a07bce1ecd52995d87f

Observation e32db511-3395-4a05-b2f4-daa3e63dbbf3 · outbound

This paper cites Autoharness: improving llm agents by automatically synthesizing a code harness,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Autoharness: improving llm agents by automatically synthesizing a code harness,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.164645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.164645Z digest=sha256:1d35f914fafa3d1073b830d7a2342bf395dd319a4911d81206b263e1f87ec41c

Observation 3e3a3567-d74d-46e1-965d-21c61d8ce21a · outbound

This paper cites Multi-agent Architecture Search via Agentic Supernet.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Multi-agent Architecture Search via Agentic Supernet

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.247014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.247014Z digest=sha256:6531b8b53a5fc20db2eb73f4bd7e27e5267d1d44a4950a01f816e5613d99bb09

Observation 554b4a78-c0c9-49bb-8e1c-30dc5a1c2eaa · outbound

This paper cites TextGrad: Automatic "Differentiation" via Text.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming TextGrad: Automatic "Differentiation" via Text

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.342591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.342591Z digest=sha256:a791c09129890dc6871816e49c993484c5d9b358195c5e0b41afc94ee4f152ee

Observation 3c0af994-60f6-4303-96f5-c5a3d88969e6 · outbound

This paper cites Test-time training with self-supervision for generalization under distribution shifts,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Test-time training with self-supervision for generalization under distribution shifts,

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.272634Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.402594Z digest=sha256:cb43dbe07229c7e463493d0eb050e4f1a1182308531cfbfd7478cdf5611165db

Observation 4761427b-17af-4cfc-94f1-f0fe0af33f58 · outbound

This paper cites Gemini CLI: An open-source AI agent for the terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Gemini CLI: An open-source AI agent for the terminal,

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.073223Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.493187Z digest=sha256:70e7ecaa079b0eb773b405bc8bae2d3b2996c14d5886b50c8d9d17ae922180ba

Observation 5a1b9b39-aa08-4a74-b822-af031cc6d786 · outbound

This paper cites Codex CLI: A lightweight coding agent that runs in your terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Codex CLI: A lightweight coding agent that runs in your terminal,

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.825124Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.564559Z digest=sha256:77ca26a64bb178f7590afd5143730756a78a2ebf15c587ee8d602595b6bb0790

Observation b8b85a14-c728-4f94-8f93-c37e7e3f8b8d · outbound

This paper cites Claw code: A clean-room open-source coding-agent CLI,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claw code: A clean-room open-source coding-agent CLI,

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.561952Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.614225Z digest=sha256:9466b4895675098b4b93db83933ce4b1d82e3774acc7b6c82f1bb585ede2cc54

Observation c49965f8-9100-48da-8537-c1ebcda2ae54 · outbound

This paper cites Hermes agent: An open-source self-hosted autonomous AI agent,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Hermes agent: An open-source self-hosted autonomous AI agent,

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.262640Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.654480Z digest=sha256:098fce4eb0a6e71ceaaa59677a05d43cfbb113f4f0616ec4347cbe5c3ea06377

Observation 72716773-1290-4acc-85d2-783456d67671 · outbound

This paper cites Claude code: An agentic coding tool for the terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude code: An agentic coding tool for the terminal,

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.011248Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.694271Z digest=sha256:f9c3d3f4ac9f669ea8204754106b48ed22250b2771f3b9f5502b9a81491b28fb

Observation 03c25b03-505b-4056-9caa-f7d8060cf3a2 · outbound

This paper cites Attention tracker: Detecting prompt injection attacks in llms,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Attention tracker: Detecting prompt injection attacks in llms,

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.823611Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.764775Z digest=sha256:49d5a067d87ecf7289fd8e27aea97fad83e6d7b6f0437f2e4715199d036acd87

Observation 6bf302bb-3a4c-4b99-9e42-3f29ecb6f5dd · outbound

This paper cites Piguard: Prompt injection guardrail via mitigating overdefense for free,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Piguard: Prompt injection guardrail via mitigating overdefense for free,

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.534030Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:47.844255Z digest=sha256:f353a7c38e8c310de167e8f6ef2e51be8f88a5de29af0fdd4f1703ea347f4fbe

Observation 4c31e5f5-4e0d-4b42-9b48-68ca1a65e058 · outbound

This paper cites Pishield: Detecting prompt injection attacks via intrinsic llm features,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Pishield: Detecting prompt injection attacks via intrinsic llm features,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.884895Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.884895Z digest=sha256:c98fd99d8651cb252c958679fa56060eba33e182789c185e0f4b3a994fc223b0

Observation b87c2d68-6b1a-4788-97cb-a45d674b1b06 · outbound

This paper cites Pisanitizer: Preventing prompt injection to long-context llms via prompt sanitization,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Pisanitizer: Preventing prompt injection to long-context llms via prompt sanitization,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.889944Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.889944Z digest=sha256:9f6bb883e9ee653b3324c5e44336c9a67c46819a3a2eccd18c5d480ab793f8c9

Observation 407bed97-eabb-4702-8561-0b84d15625bf · outbound

This paper cites PromptArmor: Simple yet Effective Prompt Injection Defenses.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PromptArmor: Simple yet Effective Prompt Injection Defenses

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.970675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.970675Z digest=sha256:70254faf2271813e6c980999b8d509374fc17a890e26f903674864648c455a86

Observation 333ca45e-6c47-4e83-9f80-76610928175c · outbound

This paper cites Defending against prompt injection with datafilter,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Defending against prompt injection with datafilter,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.140727Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.140727Z digest=sha256:b5d2f49ac98587c9943275d84430d9fb9728dfb06a4b77fb9149c6debb020f2c

Observation 059b8f4f-e9f5-4311-a80e-d78b91967332 · outbound

This paper cites Defeating Prompt Injections by Design.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Defeating Prompt Injections by Design

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.276646Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.276646Z digest=sha256:37870e3e46caec019974f083d023ab0773d4a57c3a59f17c7d2da007f8d4bf6c

Observation 82359524-7b03-44e3-a8b2-982d4129ad90 · outbound

This paper cites Drift: Dynamic rule-based defense with injection isolation for securing llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Drift: Dynamic rule-based defense with injection isolation for securing llm agents,

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.260009Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:48.451426Z digest=sha256:16ed957caaf2f699f1f89a41752587529b3cd8d7b31adee102a3c9e01c78d8c3

Observation d8392da2-dc0a-404f-91c0-488d8251085d · outbound

This paper cites AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.601504Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.601504Z digest=sha256:75c3a3016a865f426208677a4353fc3c97b685b447742ea2fec8a22f5f40437f

Observation c23152a6-c5e5-4cd2-a546-fbde8379b1b4 · outbound

This paper cites Claude opus 4.8 system card,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude opus 4.8 system card,

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:51.990541Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:48.792435Z digest=sha256:e64c871a7a3e2f592e6370a66b6793af24404233502f0d6236a9393336e97776

Observation d09fb8ad-d715-4abd-8272-6f2a4d75c615 · outbound

This paper cites Secalign: Defend- ing against prompt injection with preference optimization,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Secalign: Defend- ing against prompt injection with preference optimization,

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:51.702584Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:48.892272Z digest=sha256:792c8fbc0a344cf1a94216e6a34afd5795aafa05843b5ee1397e248e45521f11

Observation 9f07afa9-9677-4cdc-8795-3b858e9f8935 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.996878Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.996878Z digest=sha256:2715a8c4da79a5640bba0a0dd5e368e6ad78136fa295aec5f2a732b5296e843f

Observation c7126831-551e-4344-84b8-ffab5e6054f3 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 50

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.514757Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:49.034052Z digest=sha256:8f09bf2aef90fb0ac84a04ac91ba43216bba08cc0a319c9d520e695eae5f73f6

Observation f5074bf4-fd08-4704-b766-4b57a2c2cdc8 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 51

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.296756Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:49.083594Z digest=sha256:a1481b92170cc73f7fc88642d07d4d2c60c09200fc76253f4d6ab73b55dd6c75

Observation c1fea9e2-c54c-47e1-b6a8-1f3ee21011a3 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 52

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.021691Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:49.126679Z digest=sha256:013ce32a4f199904164a664ce263cd57c43d57769c8bc80bc057a650373f921d

Observation b27962e6-48cf-4f7a-b695-dcc41b949dc2 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 53

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:50.833130Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:49.191010Z digest=sha256:2c9aca7afa6522efd6390020eb0fe9096befc97c1270777240665df785b9c3e6

Observation dc2a7192-903f-4f9e-bae5-1e721339cad3 · outbound

This paper cites ## In-context examples.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ## In-context examples

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:50.559662Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:49.260862Z digest=sha256:585ed9e793d7659cbb8581f401364d66e1d8cebdf12fcc923e0e92e8397a94a6

Observation a1f25a28-a12e-4227-91e7-d3686e6a9dcf · outbound

This paper cites ## When this strategy is expected to fail.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ## When this strategy is expected to fail

Reference 55

Resolution
malformed identifier
raw_fallback, observed 2026-08-06T05:11:50.294110Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T05:11:49.315668Z digest=sha256:7479d4b398ffd713b371d545714db503014cdc1d3784519118dbad06f3f95539

Pith citing papers

No inbound Pith citation observations are available.